We primarily use the solution for log collection and security incidents as well as event management.
Cyber Security Consultant at a tech services company with 1,001-5,000 employees
Great integration capabilities with excellent scalability potential and an easy setup
Pros and Cons
- "The most valuable aspect of the solution is the integration capabilities on offer."
- "Technical support could be improved by a bit."
What is our primary use case?
How has it helped my organization?
We benefit the most from the integration on offer. IBM QRadar offers a solution to our enterprise customers, and certainly, the admin has been benefiting from it, in terms of having more visibility on what's happening on the network in terms of events, flows, et cetera, and all in real-time.
What is most valuable?
In general, the product is awesome. It's almost perfect.
The most valuable aspect of the solution is the integration capabilities on offer. It's very helpful to have so many options.
The initial setup is pretty straightforward.
The stability is good.
We've found the scalability to be excellent.
It offers all of the specifications of the hardware that we need.
What needs improvement?
The performance of the solution could be improved. Right now, it's the weakest aspect. I wish it was better.
Technical support could be improved by a bit.
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
For how long have I used the solution?
I've been dealing with the solution for five years at this point.
What do I think about the stability of the solution?
The stability of the solution is very good. It's reliable. There aren't bugs or glitches. It doesn't crash or freeze. It's been good.
What do I think about the scalability of the solution?
There's nothing better than QRadar when it comes to scalability. You can scale it to 100,000s of events per second. It can be scaled as much as you want. It has no limitations to it.
How are customer service and support?
Technical support is okay. On a scale from one to ten, I would give them an eight. They could do better, however, we are mostly happy with their level of support.
How was the initial setup?
The initial setup is not complex at all. It's quite straightforward. If a company implements this solution, they shouldn't have any issues with the setup process at the outset.
How long it takes to deploy depends on the size of the environment and the company. If it's a small enterprise, it can be done basically in a week or so. It's all about not just the department, however. It's all about collecting the log sources to integrate into it. That is where the process takes time. If the log sources are put together, things become much easier to handle. It's quicker and easier to define the rules, correlations, and reporting. The most time spent at the outset is in collecting the log sources and getting the log sources to send the data to.
The deployment process doesn't need many people. It depends on the deployment structure at first. If it treats a distributed architecture, of course, you need a couple of guys to be on board. However, then it's not only about deploying the solution, it's all about integrating the solution with different products or different platforms. That is where the time goes in. It's not a one-person job. Right from the application database, metro securities, and different controls that are in place, they all need to be integrated into the center. If we're talking about an enterprise, the team in an enterprise is equally responsible for waiting for those things to integrate.
What's my experience with pricing, setup cost, and licensing?
The NEMA licensing structure is very easy. It's far better than the previous licensing structure they had. They charge you based on the number of events per second and flows per second, and that's the beauty of it. The rest of the components are complimentary. That's it. It's not a complex process of licensing anymore. It's very simple and straightforward.
What other advice do I have?
We are resleers of QRadar.
In general, we have been quite happy with the solution. I would rate it nine out of ten.
We get excellent visibility in every aspect. It's easy to handle incidents when you really have everything in one place. You begin to know exactly what's happening on a network, and how the systems are performing and behaving.
When you compare it to other products, what I would advise is you look at how long they have been in business. This product has been in business for a very long time. You also need to look at the other integration factors, such as forensic, as they're very important. When it comes to forensic, nobody does better than what IBM Qradar Forensic does. There are other factors too - like its Watson integration, and all those things really play an equally important role.
It's not only about just the SIM, or your goals towards is going to be in building the SOC, Security Operation Center. It's all about automation as well. The integration should also look into automation capabilities. That way, you will be able to scale it up to build up a proper SOC.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Professional Services at a tech services company with 51-200 employees
Powerful user behavior analytics capabilities, and the log and process collection functionality is good
Pros and Cons
- "The most valuable feature is user behavior analytics (UBA)."
- "The whole process for support is something that needs to be improved."
What is most valuable?
The most valuable feature is user behavior analytics (UBA).
The EPS and FPS graphs are helpful.
The collecting of logs and processes is very good.
What needs improvement?
The support process needs to be improved.
Every SIEM solution has issues with plugins, as they have to connect to different log systems. It can affect security, infrastructure, and other things. IBM should continue to expand its database and cover as many systems as possible.
For how long have I used the solution?
I have been using IBM QRadar for about one year.
What do I think about the stability of the solution?
QRadar is a very stable product.
How are customer service and technical support?
The whole process for support is something that needs to be improved. You have to create a case, export the log and attach it to the case, then an engineer will clarify what you need to export and attach it to the ticket or support case, and so on. When you're working with a system that does not have good bandwidth, it makes it even more stressful. It is a lot of work and it should be easier to do.
My colleague has worked more with support and the feedback that I have heard is that they are quite good. It's the process that I am complaining about.
How was the initial setup?
The initial setup is pretty straightforward. We had several logs to integrate so it took a week and perhaps a few days.
What other advice do I have?
I would rate this product a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
General manager at a tech services company with 201-500 employees
Good detect rate with a small number of false positives, and support resolves issues quickly
Pros and Cons
- "The detection rate is good and the false positive rate is low."
- "They should speed up the incident response and also, at the same time, reduce the amount of manual effort that is required."
What is our primary use case?
We used this product as a SIEM, for information security.
How has it helped my organization?
This product collects all of the system logs and analyzes them to see if there are any security threats, or there have been any attacks. If there are, then it will alert the administrator to take the appropriate actions.
What is most valuable?
The detection rate is good and the false positive rate is low. Having a low false-positive rate is good because it means that if an alert happens then it is very likely a real attack.
QRadar is quite flexible. Out of ten, I would rate flexibility a nine.
What needs improvement?
They should speed up the incident response and also, at the same time, reduce the amount of manual effort that is required.
A nice enhancement would be the incorporation of more artificial intelligence and machine learning capabilities.
For how long have I used the solution?
We have used IBM QRadar for approximately two years.
What do I think about the stability of the solution?
I would rate the stability a ten out of ten. We have had the occasional bug or other issue but once we report it to IBM, they give us a resolution quite quickly.
How are customer service and technical support?
Technical support is quick to resolve issues.
Which solution did I use previously and why did I switch?
We developed our own application to use as a SIEM, but we switched to QRadar.
How was the initial setup?
The initial setup is complex and the deployment takes approximately three months.
What's my experience with pricing, setup cost, and licensing?
It would be great if this product were cheaper.
Which other solutions did I evaluate?
We did evaluate other options before selecting this product.
What other advice do I have?
Within the past year, IBM developed a SaaS version of QRadar, which is a nice option.
My advice for anybody who is considering this solution is to implement the latest IBM offerings together. QRadar is just one of the products, and multiple products can be combined to create the best solution for their needs.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of Information Security at a financial services firm with 501-1,000 employees
Scalable with good searching capabilities and good support
Pros and Cons
- "The most valuable feature is the searching capability and real-time operational use."
- "Some of the cloud apps need improvement."
What is our primary use case?
The primary use case of this solution is for monitoring an enterprise data center, globally for 12,000 devices.
How has it helped my organization?
It has improved the way that the organization functions.
What is most valuable?
The most valuable feature is the searching capability and real-time operational use.
What needs improvement?
Some of the cloud apps need improvement.
In the next release, I would like to see improving the stability of some of the add-on applications.
For how long have I used the solution?
I have been using IBM QRadar for two years.
We are using the current version.
What do I think about the stability of the solution?
Stability is moderate.
We have 15 people using this solution in our organization. Their positions vary from Network Engineers, Security Engineers, and Security Analysts.
What do I think about the scalability of the solution?
It's very scalable.
How are customer service and technical support?
Technical support is good.
I would rate them a nine out of ten. Their response time is good.
Which solution did I use previously and why did I switch?
Previously, I did not use another solution.
How was the initial setup?
The initial setup is complex. It's just the nature of the CM tool.
What's my experience with pricing, setup cost, and licensing?
I think that the price is fair, but we can always say that the price could be cheaper.
What other advice do I have?
Like any complex enterprise CM tool, you have to have a strong support organization. People who are good at understanding Linux operating systems. You also need a strong technical support team in-house.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder at a university with 11-50 employees
A stable, scalable, and easy-to-use solution that lets you view users' activities
Pros and Cons
- "The UBA feature is the most valuable because you can see everything about users' activities."
- "The threat intelligence functionality can be better. In addition, it can have more monitoring capabilities."
What is most valuable?
The UBA feature is the most valuable because you can see everything about users' activities.
What needs improvement?
The threat intelligence functionality can be better. In addition, it can have more monitoring capabilities.
For how long have I used the solution?
I started to use it two to three years ago.
What do I think about the stability of the solution?
Its stability is very good. I don't have any problem with it.
What do I think about the scalability of the solution?
It has good scalability. It is easy to scale, but it is a little bit expensive to scale because you have to pay a lot for everything.
How are customer service and technical support?
Their technical support is good.
Which solution did I use previously and why did I switch?
I have also used Kibana. It is a good tool. The biggest difference between Kibana and QRadar is that Kibana is an open-source SIEM integration solution. So, you need more professionals, and you have to do everything by yourself, whereas in the case of QRadar, you get everything. You are paying not only for QRadar but also for other things like support and integration. In an open-source SIEM integration solution like KIbana, you don't get these things.
How was the initial setup?
It is an easy tool for me, so the initial setup was easy for me, but it might not be easy for everyone. If you compare it with Kibana, QRadar is easier to implement.
The implementation strategy was to follow the users, collect the logs, and then implement QRadar.
What about the implementation team?
We implemented it ourselves.
What's my experience with pricing, setup cost, and licensing?
Its price is good in terms of efficiency and the number of people required for implementing various things. You might pay more in terms of money, but you might save on the number of people. For example, if you are using Kibana, you have to pay more for people or experts, which is not the case with IBM QRadar.
What other advice do I have?
When you go for this solution, you are paying not only for the product but also for integration, good staff to help you, scalability, and many other things. There are many things that you can use in QRadar. It is easy to use.
I would rate IBM QRadar a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Analyst at a manufacturing company with 10,001+ employees
Helps us monitor and generate statistics that help to illustrate what is going on in the company
Pros and Cons
- "I have found its network traffic log, network bit log, and QBI most valuable."
- "We need more features in order to create rules to detect or to meet some requirements for other areas, for example, catching the event from other authentication tools."
What is our primary use case?
We have a lot of use cases with IBM QRadar, but our primary use is for monitoring traffic and detecting tricks.
How has it helped my organization?
In terms of how IBM QRadar has improved our company, on peak days it helps us monitor and generate statistics that help to illustrate what is going on in the company. For example, SMB detects ransomware and invalid log-on. If a user is located in the United States, or we expect a login in Russia, or Ukraine, or Kenya, it is very important for us because we can detect what application they are using there, or if a hacker is trying to log in by mobile or another device.
What is most valuable?
I have found its network traffic log, network bit log, and QBI most valuable.
We have a lot of domain controllers in QRadar tracking all the security. It is also useful for identity management.
What needs improvement?
In terms of where it could be improved, this includes its forensics, incident response, and security operation center features. Additionally, some also struggle with the rules. We need more features in order to create rules to detect or to meet some requirements for other areas, such as catching the event from other authentication tools, like in Okta, for example.
In some cases, I have issues because some tools are not integrated in QRadar, such as other tools similar to DLP (Data Loss Prevention). We need to create all the integrations manually because they are not integrated in QRadar. We have a problem, for example, because they have Symantec DLP integrated in QRadar, however, it is not working because it's not detected automatically. It is not converting all the columns, but we do have the option to create manually. This is not difficult because it's very clear in the procedures.
For how long have I used the solution?
I have been using IBM QRadar for seven years.
What do I think about the stability of the solution?
QRadar's stability is great because it is always live and is always catching and monitoring all the information that we need. When we need information, it is here in QRadar.
In terms of maintenance of QRadar, my internet is secured by IBM.
What do I think about the scalability of the solution?
For me, the scalability is good.
At the moment, we have no more than 15 people working on QRadar. This includes analysts, forensics, internet response, and active directory.
How are customer service and technical support?
Tech support is good. Additionally, I can find all the information at IBM.
How was the initial setup?
In some cases, the system or the hardware do not meet the requirements to install one flow collector. Or the menu is not displayed. The menu has 10 options. If the CPU and memory are not enough, the menu shows only five or six options. But this information is not mentioned in the installation process. But it is not complex because the installation is very clear as long as we are meeting all the requirements for the CPU, memory, or the space.
The solution takes maybe four months because we have a lot of integrations.
What other advice do I have?
I would absolutely recommend QRadar because it has a lot of options to improve or detect some information.
On a scale of one to ten, I would give QRadar a 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CEO at a tech services company with 11-50 employees
Easy to install and use, but the GUI and reporting features need to be improved
Pros and Cons
- "It has very rich functionality."
- "QRadar needs to be more specialized, along the lines of what other SIEM solutions are."
What is our primary use case?
We use QRadar to detect and gather information about any product vulnerabilities and any sort of attack on the network. It's able to help detect suspicious activity that is coming into the system.
We are also selling this product.
What is most valuable?
This product is easy to install, integrate, and use.
It has very rich functionality.
What needs improvement?
QRadar needs to be more specialized, along the lines of what other SIEM solutions are. It needs to be more detailed.
Incorporating an AI component is needed, where the learning feature identifies malicious activities coming into the network.
The GUI and reporting need to be improved.
The footprint needs to be optimized because the application footprint is too heavy. The machine requires a very high amount of resources.
For how long have I used the solution?
I have been working with IBM QRadar for between three and four years.
What do I think about the stability of the solution?
This is a very stable product.
What do I think about the scalability of the solution?
QRadar is a scalable solution.
How are customer service and technical support?
Technical support is very good.
What's my experience with pricing, setup cost, and licensing?
I feel that the price is reasonable but compared to other products that are on the market, such as an offering by Microsoft, it is more expensive.
What other advice do I have?
This is a good product but there is room for improvement in several areas, including the integration of advanced data mining.
I would rate this solution a six out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Senior Manager Information Security at a tech services company with 10,001+ employees
A user-friendly, stable, and solid product with internal AI and good scalability
Pros and Cons
- "It is a pretty solid product for the type that it is representing. It is a CM solution as compared to Splunk or ArcSight from HP. It is also user friendly. It comes with some internal AI as well, in which it automatically maps multiple lots from unrelated devices and makes a smart decision to link them back and create an offense based on that. It is a smart tool."
- "A lot of information that we receive for the devices is IP-based, but it would help if we could have a default dashboard in which we can add more details about the assets for which we are receiving the information. For example, if it is a Windows or Linux device, we only get the IP for that particular device. We don't really get the name and other details of that particular device. For that, you have to drill down into your own asset management system. It would be good to have a place where we can probably add this information so that we don't have to look into other tools."
What is our primary use case?
We are using it from the compliance perspective. We need this solution to comply with HIPAA and PCI because our clients require HIPAA and PCI DSS compliance. We also use it for log management, primarily security logs, and to some extent, for operational activities, even though this tool is actually not meant for operational tasks. We do keep track of errors in our appliances like hardware, storage, and network switches through QRadar.
The main or core solution is on-premises. There is an extended arm, which is in the cloud as well for cloud integration.
How has it helped my organization?
Security incident and event management are actually the core functionalities of this solution. We receive security logs on this product and based on the received logs, we can create offense tickets that are forwarded to Netcool, which is another solution that we have. I don't have experience with that, but our integration is there so that any offense or security event is forwarded to Netcool, and a ticket is automatically generated in ServiceNow for that offense. This level of automation that we have for security-related events is done through this solution. There's no manual work involved, which obviously takes away a lot of load from the individuals who are managing the security side of it.
What is most valuable?
It is a pretty solid product for the type that it is representing i.e. SIEM. It can do automatic correlation based on the traffic that you are receiving to some extent. It has plethora of options available for third party application integration. For e.g CISCO Firepower, Palo Alto Dashboard for CISCO and Palo Alto Firewall respectively. Integration with Cloud based Log Sources is also supported via. parsers that support API Connect. This is helpful when pulling in Logs from AWS, Azure, GCP or other Cloud Based Solution like Carbon Black, Imperva etc.
What needs improvement?
A lot of information that we receive for the devices is IP-based, but it would help if we could have a default dashboard in which we can add more details about the assets for which we are receiving the information. For example, if it is a Windows or Linux device, we only get the IP for that particular device. We don't really get the name and other details of that particular device. For that, you have to drill down into your own asset management system. It would be good to have a place where we can probably add this information so that we don't have to look into other tools.
For how long have I used the solution?
I have been using this solution for about six months.
What do I think about the stability of the solution?
It is very stable. As long as you have the proper connectivity availability, it is pretty stable.
What do I think about the scalability of the solution?
Our deployment covers North America, South America and part of Europe. The product is easy to deploy and scale. Almost everyone in our organization is using this solution because most of our projects rely on this. Because of the compliance requirement, most of our projects have to be integrated with QRadar. Each business unit or each program that we have in another environment has independent access to the solutions. They might not be the end users, of course, but at least every admin team of every program unit has access to this tool so that they can see what's happening in their environment.
It also supports multi-tenancy. So, if you have multiple clients or multiple tenants in your environment, you can create logical containers for them. From a logical point of view, you can create separate disconnected containers for each client so that they can only see their data.
How are customer service and technical support?
Their technical support is quite good. I would rate them a nine out of ten.
Which solution did I use previously and why did I switch?
Yes, we switched over from NNT to QRardar. This product is more detailed. Expensive but definitely more detailed! :)
How was the initial setup?
It was pretty straightforward. These are hardware appliances. So, you need to rack and stack them. If the rack space, cabling, and other things are already done, which would typically be the responsibility of a data center team, it essentially takes three to five days. But this is only the core deployment. The fine tuning on top of it would take extra time based on the environment and how complex it is.
What about the implementation team?
It was implemented by team that included me. We have an external team for its maintenance.
What's my experience with pricing, setup cost, and licensing?
The IBM QRadar Licensing for the core Events(EPS) and Flows(FPS) is per second based. The licensing is perpetual and surely expensive but the output of the Product makes it worth your money.
What other advice do I have?
I would absolutely recommend this solution. I am pretty okay with it, and I don't have any issues with it. It has some competitors like Splunk and LogRhythm. Symantec has its own SIEM solution. ArcSight, LogRhythm, and Splunk are in the first quadrant for the Gartner research. They are leaders in their products, and they know what they're doing. It also comes down to what your company is into, how does it fit into a particular environment, and how compatible it is with a particular environment. I could have gone on the Splunk path and probably said the same thing for it as well.
I would rate IBM QRadar a nine out of ten. It is a pretty solid product.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Dynatrace
Splunk Enterprise Security
Fortinet FortiEDR
Darktrace
Microsoft Sentinel
SentinelOne Singularity Complete
HP Wolf Security
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Varonis Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?















